Uploaded image for project: 'Crucible'
  1. Crucible
  2. CRUC-8169

XSS in the view review history resource through invited reviewers - CVE-2017-18089

      The view review history resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the invited reviewers for a review.

            [CRUC-8169] XSS in the view review history resource through invited reviewers - CVE-2017-18089

            Owen made changes -
            Workflow Original: FE-CRUC Bug Workflow [ 2941852 ] New: JAC Bug Workflow v3 [ 2954329 ]
            Owen made changes -
            Workflow Original: FECRU Development Workflow - Triage - Restricted [ 2594763 ] New: FE-CRUC Bug Workflow [ 2941852 ]
            David Black made changes -
            Labels Original: CVE-2017-18089 advisory advisory-to-release cvss-medium security xss New: CVE-2017-18089 advisory advisory-released cvss-medium security xss
            David Black made changes -
            Security Original: Atlassian Staff [ 10750 ]
            David Black made changes -
            Summary Original: XSS in the review history resource through invited reviewers - CVE-2017-18089 New: XSS in the view review history resource through invited reviewers - CVE-2017-18089
            David Black made changes -
            Description Original: The review history resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the invited reviewers for a review. New: The view review history resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the invited reviewers for a review.
            David Black made changes -
            Labels Original: CVE-2017-18089 advisory advisory-to-release cvss-medium security New: CVE-2017-18089 advisory advisory-to-release cvss-medium security xss
            David Black made changes -
            Summary Original: CVE-2017-18089 New: XSS in the review history resource through invited reviewers - CVE-2017-18089
            David Black made changes -
            Description Original: The review history resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allows remote attackers to IMPACT via a VULN_INFO. New: The review history resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the invited reviewers for a review.
            David Black made changes -
            Description Original: Component in Atlassian Crucible from version 4.4.1 before version 4.4.3 allows remote attackers to IMPACT via a VULN_INFO. New: The review history resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allows remote attackers to IMPACT via a VULN_INFO.

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Affected customers:
              0 This affects my team
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: